Washington State My Health My Data Act: A Founder’s

A Seattle founder opens an analytics dashboard and sees search terms tied to pregnancy, fertility, or mental health sitting beside customer IDs. The company sells apparel, not medical care. Yet a retargeting pixel, session replay tool, or ad audience may have converted ordinary browsing into information about a person's health. That's the exposure the Washington State My Health My Data Act creates for consumer-tech companies.

The statute became effective on a staggered schedule, created a private right of action, and treats violations as violations of the Washington Consumer Protection Act, according to the Washington Attorney General's overview of the law. Founders should stop treating MHMDA as a privacy-policy editing project. The work is identifying inferred health data, controlling marketing and analytics flows, and preserving evidence that shows why each collection or disclosure occurred.

What the Washington State My Health My Data Act Actually Covers

A Seattle-based direct-to-consumer apparel brand might discover that its retargeting pixel captured a visitor's pregnancy-related search before the visitor bought anything. The brand may never have asked for a diagnosis, treatment history, or medical record. That doesn't end the analysis. If the browsing activity can reveal or support an inference about a consumer's health, the company needs to examine the flow under MHMDA.

The Act focuses on consumer health data, not only information created by hospitals or clinicians. That can include information linked to physical or mental health, reproductive health, biometric identifiers, location history associated with health facilities, and health conclusions inferred from otherwise ordinary data. The Washington Attorney General's guidance and the statute's text should be read together before a company decides that its data is “just marketing” (RCW 19.373).

A diagram illustrating how a Seattle apparel brand processes consumer health data under the My Health My Data Act.

The statute reaches beyond healthcare

A search for “best creatine supplement,” an install of a fertility app, or a visit to a location associated with healthcare can become meaningful when combined with an identifiable account, device identifier, email address, or advertising profile. The law's practical reach therefore extends to e-commerce, mobile applications, advertising technology, analytics, and telehealth.

A company operating in Washington also shouldn't assume the statute protects only Washington residents. The relevant question is where the data is collected and whether the business operates or provides goods or services in Washington. A national app can create Washington exposure through activity occurring inside the state.

Practical rule: If a vendor can connect a health-related signal to a person, device, account, or household, the founder should classify the flow before calling it anonymous.

Collection, sharing, and sale require separate analysis

MHMDA regulates more than direct collection. A pixel load, analytics event, ad audience upload, enrichment process, or inferred profile can create a separate issue involving collection, sharing, or selling. Logged telemetry may remain identifiable even when the product team calls it anonymized, particularly when other systems retain the key needed to connect the event to a consumer.

That's why founders should review the Washington My Health My Data Act guidance for businesses alongside technical records. Companies managing retired devices, servers, or storage media should also connect health-data governance with what to know about ITAD compliance, because deletion and disposal controls don't stop at the application layer.

MHMDA is best understood as a data-minimization law with litigation teeth, not a HIPAA clone. HIPAA's clinical framework doesn't tell a clothing brand whether its advertising stack inferred a consumer's reproductive-health interest. MHMDA can force that question.

Who the Compliance Deadlines Apply To

The deadline analysis starts with entity structure, not the date shown on a privacy-policy template. The Washington Attorney General states that section 10 took effect for all persons on July 23, 2023, while the Act's core consumer-data restrictions took effect on March 31, 2024 for most regulated entities and on June 30, 2024 for small businesses (Washington Attorney General).

The small-business date doesn't create a general startup safe harbor. Founders should apply the Attorney General's applicable bright-line tests, including whether the entity has fewer than 100 employees or less than $25 million in revenue. Revenue needs to be assessed at the parent level for an owned group. A two-person startup controlled by a mid-size holding company shouldn't assume the startup qualifies as exempt merely because the startup's own payroll and books look small.

Use the matrix as an entity triage tool

Effective Date Entity Type Required Compliance Step Statutory Trigger
July 23, 2023 All persons subject to section 10 Review prohibited health-data practices and geofencing exposure Section 10 took effect
March 31, 2024 Most regulated entities Operate the core consumer-health-data compliance program Core restrictions became effective
June 30, 2024 Small businesses Operate the core compliance program by the small-business deadline Small-business compliance date
June 30, 2025 Entities within the applicable geolocation-data provision Address the geolocation-data addition in the data inventory and controls Geolocation-data provision took effect

A founder should run four checks immediately:

  1. Count employees. Use the entity's real workforce, not only Washington staff.
  2. Sum revenue. Review the parent-company relationship, not merely the operating subsidiary.
  3. Inventory ownership. List holding companies, affiliates, processors, and brands that control collection decisions.
  4. Assign a deadline. Map every entity to the applicable effective date and control owner.

HIPAA-covered entities and business associates, GLBA-regulated financial institutions, and certain clinical-research contexts may fall within statutory exclusions or carve-outs. Most consumer-tech operators don't. A SaaS company, marketplace, wellness platform, or ad-supported app should document the exemption analysis instead of assuming a healthcare-related vendor's status transfers to the customer.

Contract review belongs in the same exercise. Teams handling vendor and processor terms can use resources on how to protect personal data in SaaS deals, then compare those terms with the company's MHMDA data map. The Washington data privacy and compliance resource can also help founders organize the broader program around the statute.

Mapping Your Data Flow Before You Draft a Single Notice

A privacy notice can't describe a system the company hasn't mapped. Founders should begin with a data-flow inventory that follows the signal from the first input through every warehouse, vendor, audience, model, and deletion request.

Four passes reveal the real exposure

First, enumerate input points. List forms, mobile SDKs, advertising pixels, server logs, customer-support tickets, chat histories, MCP or AI interfaces, session-replay scripts, and checkout events. Tag any field that could plausibly relate to symptoms, food choices, reproductive status, biometrics, mental health, or location.

Second, trace propagation. Follow the event into the customer data platform, warehouse, CRM, ad network, lookalike audience, experimentation tool, and third-party enrichment service. A company that deletes a field from its primary database may still leave copies in downstream systems. The inventory should record identifiers, retention behavior, access permissions, and whether a vendor receives raw values or derived segments.

Third, classify each touchpoint. Use three working labels, consumer health data, inferred consumer health data, and non-CHD, while preserving the reasoning behind each label. Geolocation deserves particular scrutiny where it places a device within 1,850 feet of a health facility, a threshold addressed in Attorney General guidance and statutory materials (RCW 19.373).

Fourth, record the legal and operational gap. Flag flows without a consent string, vendor transfers without suitable data-processing terms, ad events that include raw URLs, and analytics calls that expose search terms or free-text content. Each gap needs an owner, remediation decision, and evidence trail.

A four-step infographic illustrating the compliance process for the Washington State My Health My Data Act.

Build an inventory plaintiffs can understand

Plaintiffs' counsel won't care that a growth team called an event “anonymous” if the event can be joined to an account or advertising identifier. The defensible record shows what the company collected, what it inferred, where it sent the data, which consent applied, and when the company stopped the flow.

Teams implementing a data-classification program can use the data classification guidance to make these labels operational rather than purely legal. The classification should appear in schemas, vendor reviews, access rules, deletion workflows, and release checklists.

The following video can help teams visualize the inventory process:

The deliverable shouldn't be a static spreadsheet that nobody updates. It should connect engineering ownership to legal decisions, so a new SDK, campaign, prompt flow, or analytics integration triggers review before deployment.

Building the Separate and Distinct Privacy Notice

The MHMDA privacy notice should function as a technical control, not decorative boilerplate. The Washington Attorney General's guidance requires an accessible, separate, and distinct homepage link, and the required policy should contain the Act-required content rather than unrelated disclosures (RCW 19.373).

A general privacy policy can remain useful for other laws and business practices. It shouldn't replace the MHMDA notice when the company collects consumer health data. The link needs to appear where collection occurs, including relevant web pages, account flows, and app experiences mediated by SDKs.

Draft only what the system can support

The notice should identify:

  • Categories collected: Describe the consumer-health-data categories the inventory shows.
  • Purposes: Explain why the company collects or uses each category, including personalization, service delivery, fraud controls, or product development where applicable.
  • Sources: Identify whether data comes directly from consumers, devices, partners, public sources, or inferred activity.
  • Recipients: Describe the categories of third parties and specific affiliates that receive the data.
  • Rights mechanics: Explain how consumers can access, delete, withdraw consent, or exercise other applicable rights through the stated web address.

The notice also needs clear consent and opt-out mechanics. A consumer shouldn't have to decode whether consent covers collection, sharing, or sale. If the company sells consumer health data, the signed authorization requirement needs separate treatment, not a buried sentence in a general consent banner.

Drafting discipline: A notice that claims every possible category and purpose can create more exposure than a precise notice tied to the actual data inventory.

The Attorney General's FAQ warns against overinclusive policy placement or content. Copying HIPAA-style language, listing irrelevant practices, or claiming universal coverage can confuse consumers and undermine the rights workflow. A practical privacy policy guide from FormBackend can support general drafting organization, but counsel still needs to align the final notice with Washington's specific requirements.

An infographic detailing the five key privacy notice requirements for the Washington State My Health My Data Act.

Sign off against the live product

Legal review should test plain readability, link placement, consent language, rights URLs, version history, and synchronization with the inventory. If engineering removes a pixel but the notice still says the company shares browsing-derived health data, the document is stale. If marketing adds a new vendor without updating the notice and contract record, the company has created a documentation mismatch.

Retention matters too. The data retention policy template can help organize deletion and preservation rules, but the company should tailor those rules to its actual systems and litigation posture. The notice is only credible when product behavior, vendor contracts, and retention records tell the same story.

How the Law Is Being Enforced in Court

MHMDA has moved beyond a checklist. The first lawsuit under the law was filed in February 2025, about a year after the core requirements became effective, according to WilmerHale's analysis of the first lawsuit. That filing matters because it shows private plaintiffs are testing the statute rather than waiting for a regulatory playbook.

The case targets the theory most likely to concern non-health companies: ordinary digital-marketing infrastructure can become legally significant when browsing activity, location information, and inferred health interests are joined. A company may not possess a medical chart, but its analytics stack may still assemble a health-related profile from visits, searches, venue signals, and advertising identifiers.

The litigation theory follows the data path

The practical risk markers are familiar:

  • Raw URL capture: Query strings or page paths expose a health-related search or product interest.
  • Location joining: A device signal links browsing behavior with a sensitive facility or venue.
  • SDK propagation: An analytics or advertising SDK receives the event before the company evaluates its health implications.
  • Audience construction: The platform turns activity into a segment that can be used for targeting or measurement.
  • Inference storage: The company retains a label or score even after deleting the original event.

The first lawsuit's significance isn't limited to the defendant. It gives plaintiffs a roadmap for arguing that a non-health business collected consumer health data through marketing technology. It also puts pressure on founders to preserve implementation records, consent states, vendor terms, and deletion actions.

Early defenses won't eliminate operational risk

Standing, causation, preemption, statutory interpretation, and the boundary between identifiable and inferred data will shape early rulings. Those arguments may determine how individual claims proceed, but they don't justify leaving a known pixel or location flow untouched. A founder still needs to know what the system did and what the company told consumers.

The Act's enforcement design raises the stakes because violations are treated as per se violations of the Washington Consumer Protection Act, with both Attorney General enforcement and private suits available (Washington Attorney General). Current reporting indicates private litigation has become the main enforcement channel so far, rather than formal Attorney General actions. That makes internal documentation especially important, because plaintiffs can focus on the company's own product configuration, vendor disclosures, and policy language.

Where Founders Should Focus First

Founders shouldn't spend the next quarter rewriting every sentence of a general privacy policy. The most impactful work sits in the growth stack, where teams often deploy analytics and advertising tools faster than legal and engineering teams can classify their data.

Start with a forensic review of pixels, SDKs, session replay, location services, customer-data platforms, and campaign integrations. The review should identify whether tools receive raw identifiers, URLs, search terms, form content, device location, biometric signals, or inferred health categories. Disable unnecessary fields and document the decision instead of relying on a vendor's default configuration.

A focused action plan

A four-step compliance action plan chart for the Washington State My Health My Data Act regulations.

Forensic review comes first. Examine the highest-risk implementations before drafting promises. Checkout, account creation, health-adjacent questionnaires, free-text forms, and location-enabled features deserve priority because they create clear points for collection and consent review.

Consent should be specific. Add appropriate mechanisms where the company collects or shares consumer health data. Separate collection and sharing decisions where the law requires separate treatment, and make withdrawal practical rather than theoretical.

Vendor terms need written support. Create a vendor inventory and prioritize providers that ingest raw identifiers or build audiences. Review data-processing terms before renewal and confirm that the contract, technical configuration, notice, and deletion workflow describe the same relationship.

Monitoring should be routine. A monthly SDK audit can catch silent implementation changes. A quarterly policy refresh can reconcile the public notice with the inventory. A pre-litigation evidence-retention posture should preserve relevant versions, consent records, vendor configurations, and remediation tickets when a dispute appears likely.

Founder's priority: A smaller, accurate notice backed by a real data map is safer than a broad policy that promises controls the product doesn't operate.

The Washington Attorney General's guidance makes policy architecture part of the compliance analysis, not an afterthought. The company should test the homepage link, collection points, mobile surfaces, rights intake, and vendor deletion response as one connected system.

By Design Law Firm & Legal Consultancy, PLLC offers counsel on Washington privacy programs, policy development, data-processing agreements, incident response, and practical compliance implementation for startups and established businesses. Founders who need a MHMDA data-flow review, notice assessment, or vendor-contract analysis can visit By Design Law Firm & Legal Consultancy, PLLC to discuss the company's exposure and next steps.

Our Blog​

Related News and Articles